Re: [qubes-users] Obtaining genuine Qubos installer

2020-06-03 Thread Catacombs
If the Corona Virus pandemic is over. Go to black hat convention in Las Vegas. Collect PGP keys from those you decide you can trust. Collect some DVDs of Linux ISO’s from those you trust. Maybe similar Hacking conventions in Europe. Where did get hardware? I dunno. If I am really

Re: [qubes-users] Obtaining genuine Qubos installer

2020-06-03 Thread Mark Fernandes
Hello all, Finally finished my Wikibooks *End-user Computer Security * book that at least partly covers the topic of how to obtain software (such as the Qubes OS software) securely. The book makes specific mention of Qubes, and is

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-07 Thread tetrahedra via qubes-users
On Thu, Mar 05, 2020 at 06:33:38PM +, Mark Fernandes wrote: By the way, I consider that I am being completely reasonable with my threat model, whilst also employing critical thinking. How hard is it to go to a large PC store, and pick at random one Linux distribution, to take home, to

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread 'awokd' via qubes-users
Chris Laprise: [Snip most of Chris's well-written response; where is the thumbs up button on my email client?] > That's why things that would have been shocking (like shutting Linux out > of recent TCG updates Hadn't heard this one, but my first thought was wondering what they were trying to

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread Chris Laprise
On 3/5/20 1:45 PM, Mark Fernandes wrote: On Thu, 5 Mar 2020 at 18:21, Chris Laprise > wrote: On 3/5/20 7:31 AM, Mark Fernandes wrote: > I want to get a genuine copy of Qubos, from here in the UK (United Kingdom). > > The only way described on

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread Mark Fernandes
On Fri, 6 Mar 2020 at 14:19, Anil wrote: > ... My threat model (to the extent it may be practical to address) is that > I can't assume any kind of physical security (of devices in > particular) and I can't rely on passwords or passphrases or software > based 2FA. More than that I can't

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread Anil
> What is your threat model? My threat model (to the extent it may be practical to address) is that I can't assume any kind of physical security (of devices in particular) and I can't rely on passwords or passphrases or software based 2FA. More than that I can't reveal. > What do you trust?

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread Anil
> devices you refer to) for. You can't plan for all that (borrowing your > words) and you can't have definitive and totally confident answers for > all (even banally) possible problems. I feel strange making this > suggestion to someone who seems to be a Qubes OS developer, because > Qubes OS is

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread unman
On Thu, Mar 05, 2020 at 06:45:04PM +, Mark Fernandes wrote: > On Thu, 5 Mar 2020 at 18:21, Chris Laprise wrote: > > > On 3/5/20 7:31 AM, Mark Fernandes wrote: > > > I want to get a genuine copy of Qubos, from here in the UK (United > > Kingdom). > > > > > > The only way described on the

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-06 Thread Anil
> i trust a randomly-bought chromebook more than any overpriced device > that has "we are so secure/paranoid we walk funny" as its main selling > point. > The details of what you have been saying over the course of these emails (most of them) make sense to me in certain (perhaps most) contexts,

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mark Fernandes
On Thu, 5 Mar 2020 at 18:21, Chris Laprise wrote: > On 3/5/20 7:31 AM, Mark Fernandes wrote: > > I want to get a genuine copy of Qubos, from here in the UK (United > Kingdom). > > > > The only way described on the Quebos website at present, appears to be > > to download the ISO. > > > > I have

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread dhorf-hfref . 4a288f10
On Thu, Mar 05, 2020 at 01:21:47PM -0500, Chris Laprise wrote: > You can also qualify the model somewhat and say that an attacker cannot > successfully infect all of your (hopefully diverse) computers, so that makes the diversity bit is important. and if its mainly about validating a download,

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mark Fernandes
I know what signatures and hashes are. I've just never needed to be so bothered with them for my activities. I studied Computer Science at degree level I was recently hacked and this is why I'm so concerned about my security. I'd rather over-kill than under-kill at the moment, because later

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Chris Laprise
On 3/5/20 7:31 AM, Mark Fernandes wrote: I want to get a genuine copy of Qubos, from here in the UK (United Kingdom). The only way described on the Quebos website at present, appears to be to download the ISO. I have the classic security problem described on the website

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread dhorf-hfref . 4a288f10
On Thu, Mar 05, 2020 at 03:56:55PM +, Mark Fernandes wrote: > Well that's an idea. But still what if the software you are being 'fed' is > all tampered software, so that after replacing the computer, as soon as you > use software, you are compromised again? > Purchasing a new computer can also

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mark Fernandes
On Thu, 5 Mar 2020 at 15:42, wrote: > On Thu, Mar 05, 2020 at 03:30:26PM +, Mark Fernandes wrote: > > > So if your computer has been compromised, the methods you suggest may be > > if your computer has been compromised to the point where > you dont trust it to verify a signature, you need a

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread dhorf-hfref . 4a288f10
On Thu, Mar 05, 2020 at 03:30:26PM +, Mark Fernandes wrote: > So if your computer has been compromised, the methods you suggest may be if your computer has been compromised to the point where you dont trust it to verify a signature, you need a new computer to install qubes on. once you

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mark Fernandes
On Thu, 5 Mar 2020 at 15:01, Mike Keehan wrote: > On 3/5/20 2:40 PM, Mark Fernandes wrote: > > On Thu, 5 Mar 2020 at 13:30, Mike Keehan > > wrote: > > > > On 3/5/20 12:31 PM, Mark Fernandes wrote: > > > I want to get a genuine copy of Qubos, from here in the UK

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mike Keehan
On 3/5/20 2:40 PM, Mark Fernandes wrote: On Thu, 5 Mar 2020 at 13:30, Mike Keehan > wrote: On 3/5/20 12:31 PM, Mark Fernandes wrote: > I want to get a genuine copy of Qubos, from here in the UK (United Kingdom). > > The only way described on the

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread dhorf-hfref . 4a288f10
could you please try to at least spell the name right? this is giving my inner monk a headache... On Thu, Mar 05, 2020 at 02:40:18PM +, Mark Fernandes wrote: > The only thing relevant to this topic in the guide, appears to be the > information on verifying signatures (which is of course

Re: [qubes-users] Obtaining genuine Qubos installer

2020-03-05 Thread Mark Fernandes
On Thu, 5 Mar 2020 at 13:30, Mike Keehan wrote: > On 3/5/20 12:31 PM, Mark Fernandes wrote: > > I want to get a genuine copy of Qubos, from here in the UK (United > Kingdom). > > > > The only way described on the Quebos website at present, appears to be > > to download the ISO. > > > > I have